CHAPTER 3
Importance of Risk Identification
Helps identify what might go wrong and plan preventive actions.
Enables proactive response strategies to minimize impact.
Improves decision-making and project planning.
Encourages team ownership and continuous monitoring throughout the project lifecycle.
Inputs of Risk Identification
i. Project Management Plan Components:
Requirements, Schedule, Cost, Quality, Resource Management Plans: Highlight
uncertainties or assumptions that may pose risks.
Risk Management Plan: Defines roles, categories, and approach to risk.
Scope, Schedule, and Cost Baselines: Help detect time, scope, or budget risks.
ii. Project Documents:
Assumption Log: May uncover risky assumptions or constraints.
Cost & Duration Estimates: Show ranges and uncertainties in planning.
Issue Log: Tracks ongoing problems that may escalate to risks.
Lessons Learned Register: Helps anticipate recurring risks.
Stakeholder Register & Requirements Documentation: Identify individuals
responsible and areas vulnerable to risk.
iii. Agreements & Procurement Documents:
Contracts and supplier info may reveal risks from delays, penalties, or performance
issues.
iv. Enterprise Environmental Factors (EEFs):
Includes industry studies, benchmarking data, and external risk databases.
v. Organizational Process Assets (OPAs):
Past project files, templates, and checklists to guide risk identification.
Techniques and Tools of Risk Identification
Expert Judgment: Involves experienced professionals for insight.
Data Gathering:
Brainstorming: Team-based idea generation.
Interviews: Input from experts and stakeholders.
Checklists: Based on past projects.
Data Analysis:
Root Cause, Assumption & Constraint Analysis
SWOT (Strengths, Weaknesses, Opportunities, Threats)
Document Review
Interpersonal & Team Skills: Facilitation, collaboration, and conflict resolution.
Prompt Lists: PESTLE, TECOP, VUCA frameworks used to spark ideas.
Meetings: Risk workshops with skilled facilitators.
Outputs of Risk Identification
1. Risk Register: List of identified risks, their descriptions, potential owners, and
preliminary responses.
2. Risk Report: Summarizes risk sources and updates as other risk processes are
performed.
3. Project Document Updates: Updates to assumption logs, issue logs, and lessons learned
based on new risks identified.
Questions
1. What is the overall significance of identifying project risks?
The overall significance of identifying project risks can be understood through its key benefits
and importance:
Identifying risks helps you understand what could go wrong and how you might be able to
prevent it1. This proactive understanding is crucial for project success.
Furthermore, the process of identifying risks allows you to put together a plan for dealing
with any potential risks that might arise1. By knowing potential issues beforehand, the project
team can prepare appropriate responses.
Ultimately, risk identification helps you make better decisions when it comes to your
business1. Informed decision-making is facilitated by a clear understanding of potential threats
and opportunities.
The key benefit of the Identify Risks process is the documentation of existing individual
project risks and the sources of overall project risk2. This documentation ensures that the
project team is aware of potential risks and can respond appropriately to them.
2. What is an issue log used for?
Based on the sources, an issue log is used as a tool for documenting and tracking problems
that arise during a project.
Specifically, the uses of an issue log include:
•Recording issues in detail1. It records each issue including its description, who reported it, its
priority, and the steps needed to resolve it.
•Monitoring each problem's progress1. By organizing issues in one place, it helps you track
where each issue stands.
•Prioritizing urgent issues1. It allows for assessing the issue's urgency to help prioritize
resources.
•Allocating resources effectively1.
•Maintaining clear communication among stakeholders1. Everyone involved can see the
status of current issues, making it easier to stay aligned and avoid misunderstandings1.
•Identifying patterns and recurring problems, which helps in taking preventive actions in
future projects.
•Capturing any new issues uncovered or changes in currently logged issues during processes
like Identify Risks4.
In essence, the issue log serves to keep track of problems, ensures the team knows their status
and responsibility, facilitates communication, helps in resource management and
prioritization, and provides a historical record for process improvement1....
3. Name outputs of Identify Risks.
Based on the sources provided, the outputs of the Identify Risks process are primarily
documented in three forms:
•Risk Register
•Risk Report
•Project Documents Updates
Let's look at each of these in more detail:
[Link] Register: This is a key output completed after the Identify Risks process1. The content of
the risk register may include:
◦List of identified risks1. Each individual project risk receives a unique identifier1. Identified
risks are described in detail to ensure unambiguous understanding1. A structured risk statement
can be used to differentiate risks from their cause(s) and their effect(s)1.
◦Potential risk owners4. If a potential risk owner is identified during the process, they are
recorded in the risk register4. Risk owners are individuals responsible and accountable for
ensuring proper risk management4.
◦List of potential risk responses4. If a potential risk response is identified during the process, it
is recorded in the risk register4. This will be confirmed later in the Plan Risk Responses
process4.
◦Additional data may also be recorded for each identified risk, depending on the risk register
format specified in the risk management plan4.
[Link] Report: This report presents information on the sources of overall project risk and
summary information on identified individual project risks. The risk report is developed
progressively throughout the Project Risk Management process, with results from later processes
(like qualitative/quantitative analysis and response planning/implementation/monitoring) also
being included as they are completed.
[Link] Documents Updates: Several project documents may be updated because of the
Identify Risks process:
◦Assumption log: During the Identify Risks process, new assumptions may be made, new
constraints identified, and existing ones revisited or changed, leading to updates in the
assumption log.
◦Issue log: The issue log should be updated to capture any new issues uncovered or changes
in currently logged issues3. (As we discussed previously, an issue log is a tool for documenting
and tracking problems that arise during a project, recording details like description, reporter,
priority, and steps needed for resolution5).
◦Lessons learned register: Information on techniques effective in identifying risks can be added
to the lessons learned register to improve performance in later phases or other projects3.
4. List of three data gathering techniques.
Three data gathering techniques that can be used in the Identify Risks process are:
[Link]: The project team usually performs brainstorming, often with a
multidisciplinary set of experts who are not part of the team1. Ideas are generated under the
guidance of a facilitator, either in a free-form brainstorm session or one that uses more structured
techniques2. Most risk workshops include some form of brainstorming3.
[Link]: A checklist is a list of items, actions, or points to be considered2. It is often used as
a reminder2. Risk checklists are developed based on historical information and knowledge that
has been accumulated from similar projects and from other sources of information2.
[Link]: Individual project risks and sources of overall project risk can be identified by
interviewing experienced project participants, stakeholders, and subject matter experts4.
5. Define the Identify Risks process.
Based on the sources and our conversation history, the Identify Risks process is defined as the
process of identifying individual project risks as well as sources of overall project risk, and
documenting their characteristics.
Essentially, it's about understanding what could go wrong during a project. This process is
crucial because its key benefit is the documentation of existing individual project risks and
the sources of overall project risk. By having this documentation, the project team is equipped
to respond appropriately to identified risks.
The Identify Risks process is not a one-time activity; it is an iterative process. This means it is
performed throughout the project life cycle, as new individual project risks may emerge and
the level of overall project risk can change as the project progresses3.
While key participants like the project manager, team members, specialists, customers, and
subject matter experts are often involved1, all project stakeholders should be encouraged to
identify individual project risks4. Involving the project team is particularly important to foster
a sense of ownership and responsibility for the risks and associated response actions.
When describing and recording risks, the process emphasizes using a consistent format for risk
statements to ensure each risk is understood clearly and unambiguously. This consistent
format can help differentiate risks from their causes and effects.
The process utilizes various inputs, tools, and techniques to achieve its objective of identifying
and documenting risks, ultimately leading to key outputs like the Risk Register and Risk Report
and updating other project documents such as the Assumption Log and Issue Log.
6. Name a risk data gathering technique.
Based on the sources provided, a risk data gathering technique is Brainstorming.
7. What are outputs of Identify Risks process?
Based on the sources and our conversation history, the primary outputs of the Identify Risks
process are documented information about the risks and updates to various project documents.
The key outputs are:
•Risk Register
◦This is completed upon the completion of the Identify Risks process1.
◦Its content may include a list of identified risks1. Each individual project risk receives a unique
identifier in the register1. Identified risks are described in detail to ensure unambiguous
understanding1. A structured risk statement may be used to distinguish risks from their cause(s)
and their effect(s.
◦It also records potential risk owners, where identified during the process2. Risk owners are
individuals responsible and accountable for ensuring proper risk management2.
◦A list of potential risk responses is also recorded if identified during this process; these will be
confirmed later in the Plan Risk Responses process2.
◦Additional data may be recorded depending on the risk register format specified in the risk
management plan.
•Risk Report
◦This report presents information on the sources of overall project risk.
◦It includes summary information on identified individual project risks.
◦The risk report is developed progressively throughout the Project Risk Management process,
with results from subsequent processes (like Perform Qualitative/Quantitative Risk Analysis,
Plan/Implement/Monitor Risks) also being included as they are completed.
•Project Documents Updates4
◦Several project documents may be updated as a result of process.
◦The Assumption log should be updated with any new assumptions made, new constraints
identified, or existing ones revisited and changed during the Identify Risks process4.
◦The Issue log should be updated to capture any new issues uncovered or changes in
currently logged issues. As we discussed previously, the issue log is a tool for documenting and
tracking problems that arise during a project, detailing descriptions, reporters, priorities, and
steps for resolution.
◦The Lessons learned register can be updated with information on techniques that were
effective in identifying risks, helping to improve performance in later phases or other projects.
8. List of three elements of an issue log.
Based on the sources, an issue log is a tool used for documenting and tracking problems that
arise during a project1. It records details about each issue to help monitor its progress, prioritize
urgent matters, and maintain communication among stakeholders1.
The sources list several elements that are typically included in an issue log. Here are three of
them:
[Link] ID: This is a unique identifier for each issue, which makes it easy to reference2.
[Link]: This provides a clear, concise summary of the issue so all team members can
understand it.
[Link] Level: This is used to assess the issue’s urgency (e.g., high, medium, or low) to help
you prioritize resources.
9. What is one output of Identify Risks?
Based on the sources and our conversation history, one output of the Identify Risks process is the
Risk Register.
The Risk Register is completed upon the completion of Identify Risks process1. Its content may
include a list of identified risks2, potential risk owners where identified2, and a list of potential
risk responses where identified. Additional data may also be recorded depending on the risk
register format specified in the risk management plan.
10. What are three tools for Identify Risks?
Based on the sources, there are several tools and techniques used in the Identify Risks process1.
Here are three of them:
[Link] Judgment: Expertise should be considered from individuals or groups with specialized
knowledge of similar projects or business areas1. Such experts are identified by the project
manager and invited to consider all aspects of individual project risks and sources of overall
project risk, based on their previous experience and areas of expertise1.
[Link]: This is a data-gathering technique where the project team usually performs
brainstorming, often with a multidisciplinary set of experts who are not part of the team1. Ideas
are generated under the guidance of a facilitator. Most risk workshops include some form of
brainstorming3.
[Link]: This is another data-gathering technique2. A checklist is a list of items, actions, or
points to be considered, often used as a reminder4. Risk checklists are developed based on
historical information and knowledge accumulated from similar projects and other sources4.
11. What are key Identify Risks inputs?
Based on the sources, the Identify Risks process utilizes several key inputs to help the project
team identify and document potential risks. These inputs are primarily drawn from the project
management plan components, various project documents, agreements, procurement
documentation, enterprise environmental factors, and organizational process assets.
Here are the key inputs for the Identify Risks process:
•Project Management Plan Components:
◦Requirements management plan: Defines how requirements will be collected, analyzed,
documented, managed, and tracked throughout the project cycle
◦Schedule management plan: May identify areas subject to uncertainty or ambiguity2.
◦Cost management plan: May identify areas subject to uncertainty or ambiguity2.
◦Quality management plan: May identify areas subject to uncertainty or ambiguity, or where
key assumptions have been made that might give rise to risk.
◦Resource management plan: May identify areas subject to uncertainty or ambiguity, or
where key assumptions have been made that might give rise to risk.
◦Risk management plan: Provides information on risk-related roles and responsibilities,
indicates how risk management activities are included in the budget and schedule, and
describes categories of risk, which may be expressed as a risk breakdown structure3.
◦Scope Baseline: Includes deliverables and criteria for their acceptance, some of which might
give rise to risk.
◦Schedule Baseline: May be reviewed to identify milestones and deliverable due dates that are
subject to uncertainty or ambiguity, or where key assumptions have been made that might
give rise to risk.
◦Cost Baseline: May be reviewed to identify costs or funding requirements that are subject to
uncertainty or ambiguity, or where key assumptions have been made that might give rise to
risk.
•Project Documents5...:
◦Assumption log: Assumptions and constraints recorded in the assumption log may give rise to
individual project risks and may also influence the level of overall project risk. The
assumption log includes elements like name and description, category, owner/person responsible,
date first logged, due date, and a rating for uncertainty (high/medium/low).
◦Cost Estimates: Provide quantitative assessments of project costs, ideally expressed as a range,
indicating the degree of risk. A structured review of these documents may indicate that the
current estimate is insufficient and poses a risk to the project5.
◦Duration Estimates: Provide quantitative assessments of project durations, ideally expressed as
a range, indicating the degree of risk. A structured review may indicate that the current estimate
is insufficient and poses a risk to the project.
◦Issue Log: Although sometimes listed as an input6, the issue log is also primarily a tool for
documenting and tracking problems that arise during a project. It captures details like
description, reporter, priority, and steps needed to resolve issues6. While an output of this
process involves updating the issue log, the log itself contains information about existing
problems that could highlight potential risks.
◦Lessons Learned Register: Lessons learned about risk identified from earlier phases of the
project are reviewed to determine whether similar risks might recur during the remainder of the
project.
◦Requirements Documentation: Lists the project requirements and allows the team to identify
those that could be at risk.
◦Resource Requirements: Provide quantitative assessments of project resource requirements,
ideally expressed as a range, indicating the degree of risk. A structured review may indicate that
the current estimate is insufficient and poses a risk to the project.
◦Stakeholder Register: Indicates which individuals or groups might participate in identifying
risks to the project. It also details those individuals who are available to act as risk owners.
•Agreements: If external procurement is required, agreements may contain information like
milestone dates, contract type, acceptance criteria, awards, and penalties that can present threats
or opportunities.
•Procurement Documentation: Documentation such as seller performance reports, approved
change requests, and inspection information may introduce additional individual project risks.
•Enterprise Environmental Factors: External factors that can influence the Identify Risks
process include published material (commercial risk databases, checklists, academic studies,
benchmarking results, industry studies).
•Organizational Process Assets: Internal assets that can influence the Identify Risks process
include project files (actual data), organizational and project process controls, risk statement
formats, and checklists from previous similar projects.
CHAPTER 4
ANALYSING AND EVALUATING PROJECT RISK
Perform Qualitative Risk Analysis
Definition & Purpose
This process involves analyzing identified project risks and prioritizing them using a pre-
defined scale (based on probability and impact).
It helps determine which risks require a response plan, further analysis, or monitoring,
enabling informed and focused risk management.
The process is conducted iteratively throughout the project lifecycle and sets the
foundation for quantitative risk analysis, if required.
Key Objectives
1. Assess risks based on likelihood (probability) and consequences (impact).
2. Prioritize risks to direct resources to high-impact threats/opportunities.
3. Assign risk owners to take charge of responses.
4. Support planning by identifying low-priority risks for watchlists.
Input
Risk Management Plan: Defines roles, budget, risk categories, scales for
probability/impact, and thresholds.
Project Documents:
Risk Register
Assumption Log
Stakeholder Register
Enterprise Environmental Factors (EEFs): Industry studies, databases.
Organizational Process Assets (OPAs): Historical data, lessons learned, templates.
Tools & Techniques
1. Data Gathering:
Interviews and expert judgment
Meetings and brainstorming
2. Data Analysis:
Probability & Impact assessment
Risk categorization (using Risk Breakdown Structure)
Root cause analysis
3. Data Representation:
Probability-Impact Matrix (e.g., Red = High Risk, Green = Low Risk)
Ordinal scales like High/Medium/Low or Likert scales.
4. Interpersonal Skills:
Collaboration, communication, negotiation, and decision-making
Steps in the Process
1. Select Risk Characteristics
Use pre-defined criteria (probability, impact, urgency).
Output: Risks categorized as High, Moderate, Low.
2. Collect & Analyze Data
Use valid, unbiased data sources.
Ensure quality through reviews and structured assessments.
3. Prioritize Risks
Assess probability (0 to 1 or 0% to 100%) and impact (Very Low to Very High).
Use Impact/Probability Matrix to visualize and rate risks.
4. Categorize Risks
Group by sources (technical, environmental, commercial).
Helps focus response efforts and develop common strategies.
5. Document Results
Risks recorded in the Risk Register.
High-priority risks: flagged for detailed response planning.
Low-priority risks: moved to a watch list.
Output
1. Risk Register Updates
Probability, impact scores
Priority ranking
Assigned risk owner
Risk categories and urgency
2. Risk Report Updates
High-priority risks summary
Updated risk exposure profile
3. Project Document Updates
Assumption Log (revised assumptions)
Issue Log (new risks/issues)
Watchlist for low-priority risks
Conclusion
Performance Qualitative Risk Analysis is essential for risk prioritization, resource optimization,
and focused response planning. It ensures that project risks are continuously evaluated and
managed with clarity, enabling better project outcomes.
Perform Quantitative Risk Analysis
Definition & Purpose
This process involves numerically analyzing the combined effect of individual project
risks and overall uncertainty on project objectives (cost, time, scope, quality).
It quantifies risk exposure, supports decision-making, and helps in prioritizing and
allocating contingency reserves.
Performed only when required, typically on complex or high-risk projects.
Key Objectives
1. Estimate overall risk exposure.
2. Support risk response planning with numerical data.
3. Identify key drivers of project risk.
4. Determine the probability of project success and resource sufficiency.
Input
1. Project Management Plan
Risk Management Plan: Specifies if and how quantitative analysis will be performed.
Scope, Schedule, and Cost Baselines: Starting points to measure risk impact.
2. Project Documents
Risk Register
Risk Report
Assumption Log
Cost & Duration Estimates
Forecasts
Resource Requirements
3. Enterprise Environmental Factors
Industry benchmarks, risk studies, and databases.
4. Organizational Process Assets
Historical data and reports from past projects.
Tools & Techniques
1. Expert Judgment
Risk modeling experts help select techniques, interpret data, and build models.
2. Data Gathering
Collect relevant data for assumptions, estimates, and historical risks.
3. Interpersonal & Team Skills
Facilitate risk assessment workshops and discussions.
4. Data Analysis Techniques
a. Sensitivity Analysis
Identifies which risks impact objectives the most.
Results are often shown in Tornado Diagrams (longer bars = higher impact).
b. Expected Monetary Value (EMV) Analysis
Calculating average outcome:
EMV = Probability × Impact
Useful for building contingency reserves and decision trees.
c. Decision Tree Analysis
Graphical techniques show choices, risks, and outcomes.
Help select the path with the highest expected value.
d. Monte Carlo Simulation
Uses random sampling to simulate hundreds or thousands of project outcomes.
Applied to cost and schedule using probability distributions (e.g., Triangular).
Results in a range of possible outcomes and probability curves.
Example Techniques
❖ Triangular Distribution (used in Monte Carlo):
❖ Tornado Diagram Characteristics:
Risks listed top-to-bottom by impact.
Helps focus on high-impact uncertainties.
❖ EMV Example Summary:
If multiple risks with costs and probabilities are analyzed:
Combine EMVs to determine the total reserve needed.
e.g., total EMV = $49,000 ⇒ add this to project budget.
Output
1. Detailed Probabilistic Risk Analysis
o Identifies top risks, critical path threats, and overall exposure.
2. Prioritized Risk List
o Shows which risks have the greatest impact (positive or negative).
3. Contingency Reserve Determination
o Helps define extra time/budget required to meet confidence levels.
4. Risk Report Updates
o Updated with quantitative findings, graphs, and simulations.
5. Trends Over Time
o Repeated analysis can reveal shifts in risk profile.
6. Recommended Risk Responses
o Informed suggestions for mitigation or exploitation based on analysis.
Conclusion
Perform Quantitative Risk Analysis provides data-driven insights to guide risk-based decisions,
improve project confidence levels, and ensure effective resource planning. When applied
correctly, it helps project managers respond proactively to uncertainty and protect project
objectives.